🔪 Slice For Life - Part 2 🔪
4.69K subscribers
1.07K photos
59 videos
964 links
Download Telegram
🚨 Remus information-stealing malware offered as a service

A forum seller is advertising Remus, a malware-as-a-service stealer promoted with 24/7 support, an easy-to-use control panel, configurable builds, automated log processing, Telegram integration, and a claimed callback rate of up to 90%.

The seller claims Remus can collect:

• Data from 21 browsers, 16 cold wallets, and 38 applications

• Credentials, cookies, autofill data, browser history, saved notes, and payment card numbers with CVVs

• Cryptocurrency seed phrases, private keys, wallet files, and MetaMask data

• Data from 181 Chromium wallet extensions, 43 password managers, 11 note extensions, and 13 two-factor authentication extensions

• Data from 42 Mozilla wallet extensions, 22 password managers, and four authentication extensions

• Files from selected folders using configurable paths, masks, depth limits, exclusions, and maximum file sizes

The management panel reportedly includes:

• Full and incomplete log scoring with detailed statistics

• Search filters for cookies, passwords, browser history, and other collected data

• AND/OR search conditions and preconfigured filters for different targeting categories

• Instant browser-based log viewing without downloading the archive

• Unlimited log exports and simultaneous download tasks

• Per-build statistics pages and configurable collection rules

• Telegram alerts, bots, loaders, and callback notifications

• Support for operator-controlled collection servers deployed through Docker

The malware is reportedly written in C++ and uses:

• System calls and a custom communication protocol

• Encrypted configurations and encrypted data transmission

• Compressed logs, caching, backup servers, and microservice infrastructure

• Build obfuscation and a small executable footprint

• Claimed EDR bypass capabilities

• Claimed detection of virtual machines, honeypots, and dedicated analysis servers

• A claimed automated MetaMask wallet brute-force feature

Pricing is advertised at:

• Base: $250 per month

• Pro: $500 per month

• Enterprise: $1,000 per month

Higher-priced plans reportedly add more builds, filters, Telegram bots, loaders, concurrent exports, team accounts, worker dashboards, API access, granular permissions, and DLL, PowerShell, or in-memory execution options.

This claim is currently unverified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
1
🚨‼️ The Gentlemen Ransomware claims 35 victims

🇮🇩 Pertamina - Indonesia’s state-owned energy company operating across oil, gas, refining, petrochemicals, and renewable energy. The listing claims more than 1.2 TB of NDA files, HR and employee data, technical drawings, source code, banking information, contracts, and internal communications.

🇦🇹 Ökovolt Solartechnik - An Austrian solar-energy company specializing in photovoltaic system planning, installation, maintenance, and energy-storage solutions.

🇨🇴 Ecopetrol - Colombia’s state-controlled energy company engaged in oil and gas exploration, production, refining, transportation, and renewable-energy projects.

🇺🇸 Total Auto Business Solutions - A California-based automotive software company providing shop-management, inventory, accounting, and customer-relationship tools.

🇺🇸 Optiforms - A California precision manufacturer specializing in electroforming, CNC machining, optical components, and advanced surface finishes.

🇺🇸 Chemco Systems - An Illinois-based manufacturer of bulk chemical-storage, handling, feeding, and water-treatment systems.

🇺🇸 World Wide Fittings - An Illinois manufacturer of precision-engineered steel and stainless-steel hydraulic tube and pipe fittings.

🇵🇪 Municipalidad de San Luis - The municipal government serving the San Luis district of Lima, Peru.

🇺🇸 Peachtree Group - An Atlanta-based investment management firm focused on commercial real estate, private credit, and hospitality financing.

🇺🇸 Known - A New York-based marketing, media, analytics, and creative agency serving major global brands.

🇵🇱 Paula Fish - A Polish seafood company specializing in the catching, processing, freezing, and distribution of fish products.

🇮🇱 Amicell - An Israeli manufacturer of custom battery packs, chargers, and battery-management systems for industrial and specialized applications.

🇮🇱 Efrata College of Education - An Israeli academic institution providing undergraduate and graduate teacher-training and education programs.

🇧🇷 Municipal Chamber of Serra - The legislative body responsible for municipal lawmaking and oversight in Serra, Espírito Santo, Brazil.

🇺🇸 Conecsus - A Texas-based recycler and refiner recovering valuable metals from electronic waste and solder-processing materials.

🇩🇿 Orsima - An Algerian IT-services company providing digital transformation, cybersecurity, cloud, networking, and managed technology solutions.

🇺🇸 Clear Vision Signs - A Florida signage company providing architectural signs, graphics, wayfinding systems, ADA-compliant signage, and installation services.

🇺🇸 Precision Concrete Pumping - A New York and New Jersey concrete-pumping contractor serving commercial, industrial, municipal, and residential projects.

🇵🇱 Bater - A Polish manufacturer of industrial traction and stationary battery systems used in forklifts, renewable energy, rail, and telecommunications.

🇸🇬 Premier Fiduciary - A fiduciary and corporate-services provider offering fund administration, trustee, compliance, and private-wealth support.

🇺🇸 Preferred Tool & Die - A Connecticut precision manufacturer producing custom metal and plastic components for medical, automotive, electrical, and consumer industries.

🇺🇸 Partition Specialties - A California and Nevada interior contractor specializing in movable partitions, demountable walls, glass systems, and acoustic dividers.

🇺🇸 CRB Group - A U.S. engineering, architecture, construction, and consulting firm serving the life-sciences and food-and-beverage industries.

🇺🇸 Hutch Paving - A Michigan asphalt and concrete paving contractor providing resurfacing, maintenance, sealcoating, and new construction services.

🇮🇪 OHK Energy - An Irish renewable-energy company installing solar panels, heat pumps, battery storage, and electric-vehicle chargers.

🇺🇸 CFS - A Massachusetts marketing-support company providing printing, promotional products, fulfillment, and project-management services.
2
🔪 Slice For Life - Part 2 🔪
🚨‼️ The Gentlemen Ransomware claims 35 victims 🇮🇩 Pertamina - Indonesia’s state-owned energy company operating across oil, gas, refining, petrochemicals, and renewable energy. The listing claims more than 1.2 TB of NDA files, HR and employee data, technical…
🇺🇸 Acosta & Sons - A New York appliance sales and repair business serving residential customers, landlords, and property managers.

🇨🇦 Saturn Industries - A Manitoba manufacturer of custom trailers, overhead-lifting equipment, and industrial products for construction, mining, marine, and aerospace customers.

🇮🇳 Kosh Innovations - An Indian precision-engineering company specializing in injection molding, sheet-metal components, electronics manufacturing, and automotive parts.

🇸🇪 Krafman - A Swedish credit-reporting and debt-collection platform providing business and individual credit checks.

🇹🇿 Salama Medicals Distributors - A Tanzanian importer and distributor of pharmaceuticals, medical devices, and surgical equipment.

🇸🇦 Salem Saleh Babgi Group - A Saudi conglomerate operating across automotive distribution and other commercial sectors.

🇺🇸 Additive Manufacturing - A Nevada manufacturing company specializing in 3D printing, rapid prototyping, CNC machining, production tooling, and assembly.

🇺🇸 Kenaitze Indian Tribe - A federally recognized Alaska Native tribe providing healthcare, education, elder care, cultural, and community services.

🇨🇱 Las Cenizas - A Chilean mining company producing copper concentrates and cathodes from operations in Cabildo, Taltal, and other locations.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ Amgen Inc. has filed form 8-K due to a Cybersecurity incident

https://www.sec.gov/Archives/edgar/data/318154/000031815426000119/amgn-20260729.htm

In July 2026, Amgen Inc. (the "Company") identified unauthorized activity involving data stored in cloud environments hosted by third-party cloud service providers. Upon detecting the activity, the Company activated its cybersecurity response plan, implemented containment measures, and engaged independent cybersecurity forensic experts.

The Company has since learned that some of its data, including proprietary data, patient protected health information, and other information, has been exfiltrated from these cloud environments. To date, the Company has not identified any impact to its products, manufacturing operations, or financial reporting systems, or to the Company's ability to meet patient needs. The investigation remains ongoing. The Company continues to assess whether, and/or the extent to which, patient, confidential business information, intellectual property, research and development, or other information may have been accessed, acquired, or exfiltrated and to evaluate the potential impact of the incident on the Company.

On July 29, 2026, in connection with our evaluation of the volume of the files that appear to have been impacted and the potential that the types of information in such files could be sensitive, the Company determined that this incident is material.

The Company believes, as of the date of this Current Report on Form 8-K, that the incident is not reasonably likely to have a material impact on the Company's financial condition or results of operations.

The Company takes its obligation to safeguard privacy and security of its patients’ data very seriously. The Company continues to evaluate applicable regulatory and legal notification requirements and will make all required notifications based on its findings, including to impacted patients.

To the extent any information required by Item 1.05(a) of Form 8-K was not determined or was unavailable at the time of this filing, the Company will amend this Current Report on Form 8-K as such information is determined or becomes available.
Forwarded from Dark Web Informer - Private
Cybersecurity Incident Disclosure

Fri, 31 Jul 2026 16:03:44 EDT
A cybersecurity incident has been disclosed by AMGEN INC, Inc CIK: 0000318154, Ticker: $AMGN.

View SEC Filing
yesitsme: A Python-based OSINT tool that helps users locate Instagram profiles potentially connected to a person’s name, email address, or phone number.

GitHub: https://github.com/0x0be/yesitsme

The script collects usernames indexed by Dumpor and uses Toutatis to obtain partially masked contact details for each account.

It then compares those details with the information provided by the user, reducing the amount of manual research required.
Scraperr: A self-hosted webscraper

GitHub: https://github.com/jaypyles/Scraperr
🔥1
Please open Telegram to view this post
VIEW IN TELEGRAM
2
🚨🇹🇷 Denizli Private Egekent Hospital patient data allegedly leaked

A forum actor claims to have leaked a database belonging to Denizli Private Egekent Hospital in Turkey. The post advertises approximately 20,000 patient records and provides a free download link.

The data allegedly includes national identification numbers, names, gender, dates and places of birth, parents’ names, home addresses, visit dates and times, departments, doctors, room numbers, diagnoses, prescription numbers, prescribed medications, treatment fees, payment methods, and insurance provider information.

This claim is currently unverified.

💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
‼️🇮🇩 A forum seller is offering alleged backend access to an Indonesian government system for $200, with escrow support offered for the transaction. No further details on the specific agency or data exposed are provided.

💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
😭2
🚨 Kyndryl Azure/Entra tenant data allegedly offered for sale

A forum actor claims to be selling an internal data dump belonging to Kyndryl, a global IT infrastructure services company operating across more than 60 countries. The actor says the data was downloaded directly from the company’s Azure/Entra environment using compromised credentials.

The listing advertises more than 170,000 records, including employee accounts, service accounts, administrative roles, display names, email addresses, and other tenant account information.

A sample containing 2,200 records was published alongside the post.

This claim is currently unverified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇮🇶 Qi Mobile ISC customer data allegedly leaked

A forum actor claims to have breached Qi Mobile ISC, an Iraqi mobile telecommunications and digital services provider, and published a 2.03GB uncompressed database containing 970,949 unique customer profiles.

The listing advertises:

• 970,949 unique phone numbers
• 11,168 unique account numbers
• 357,504 unique IP addresses
• Session cookies, JWTs, and JSESSIONIDs
• KYC verification, payment, balance, and CSRF token activity
• Devices, applications, languages, API endpoints, REST paths, and session events
• First and last request, session, and activity timestamps

The actor also exposed an internal IP address and a Telegram bot token associated with the company’s infrastructure.

This claim is currently unverified.

💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
🚨 PedidosYa customer credentials allegedly leaked

EsqueleSquad claims to have leaked a database associated with PedidosYa, a Latin American food delivery platform operating across multiple countries.

The post advertises more than 9.25 million customer records connected to:

• Argentina
• Bolivia
• Chile
• Ecuador
• Paraguay
• Peru
• Uruguay
• Venezuela

The exposed data allegedly includes:

• Email addresses
• BLAKE3 password hashes
• Home addresses
• Country information

The actor published a database sample and claims the full SQL dump is available for free.

This claim is currently unverified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing